'Yellow Teams' Are Defining the Future of AI Security
Yellow teams simultaneously design AI attacks and defenses, proactively hardening systems. Unlike separated red/blue teams, they're embedded in development for real-time collaboration.
ACTIVE THREATS: How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know • AVEVA Pipeline Integrity Monitor ACTIVE THREATS: How a hole in Lenovos login system let hackers walk into 5,000 Dropbox accounts • The US military just turned off ad tracking on its phones. Maybe you should too • Hackers exploit Tencent app flaw to deploy GrayRabbit malware • CRPx0 ransomware: what you need to know • AVEVA Pipeline Integrity Monitor
The full HackWire archive — 3,891 stories, newest first.
Yellow teams simultaneously design AI attacks and defenses, proactively hardening systems. Unlike separated red/blue teams, they're embedded in development for real-time collaboration.
CrashStealer, a new macOS infostealer, impersonates Apple's crash reporter to steal passwords, keychain data, and crypto information. It exploits macOS users' false sense of security through convincing social engineering.
Jscrambler npm package was compromised with infostealer malware, affecting approximately 1,500 developers before detection. The supply chain attack harvested sensitive data from developers' machines, exemplifying the increasing threat of compromised development tools.
EU sanctions 9 Russians and 4 entities for decade-long cyber espionage targeting European critical infrastructure. The FSB's 16th Centre allegedly conducted sabotage operations on power plants, railways, and heating systems across at least 9 nations, escalating tensions over state-sponsored cyberatt
Blackhat hacker Jesse McGraw served 11 years in prison for cyber crimes. Now a cybersecurity advocate, his redemption story challenges the industry on rehabilitation and second chances.
GigaWiper is a modular malware combining persistent C2 with on-demand destructive payloads like disk wiping and fake ransomware. Unlike traditional wipers, it lets attackers control when and how they destroy systems.
ModHeader (1.6M users) was removed from Chrome and Edge after researchers found dormant browsing-data collector code embedded in it. The inactive but functional malware revealed critical gaps in browser extension security screening.
CrashStealer is a notarized macOS malware bypassing Gatekeeper to steal credentials, crypto, and keychain data. Built in C++, it exploits Apple's code-signing system for distribution, representing a new threat model where attackers abuse legitimate security mechanisms.
CISA contractor exposed 844MB of sensitive data—including AWS GovCloud credentials and plaintext passwords—on a public GitHub repo for six months, revealing critical failures in secret scanning and incident response protocols.
MemGhost exploits AI agent memory files—one email injects false data that persists undetected across sessions. The attack achieves 87.5% success, permanently poisoning agent behavior.
Progress ShareFile vulnerability forced urgent shutdowns amid accelerating supply chain compromises via npm packages. The gap between disclosure and active exploitation is shrinking rapidly.
Lidl suffered a data breach via third-party vendor across Germany, Belgium, and the Netherlands. Customer names, emails, and birthdates were exposed; passwords and payment data may also be at risk.
Attackers are actively exploiting file upload vulnerabilities in two Joomla extensions (iCagenda and Balboola Forms) to gain remote code execution. CISA added both CVEs to its Known Exploited Vulnerabilities catalog with maximum severity, ordering federal agencies to patch immediately.
Zimbra patched a critical vulnerability allowing code execution when users open malicious emails—no additional interaction required. Affecting thousands of organizations globally, the flaw transforms email into a direct exploitation channel for attackers.
A critical RabbitMQ vulnerability allows unauthenticated attackers to extract OAuth secrets and seize full control of the message broker, threatening enterprises that rely on it for mission-critical message routing and microservices communication.
Cybersecurity saw 37 M&A deals in June 2026, with major players like 1Password, Accenture, and Cisco driving unprecedented consolidation. The surge signals industry transformation but raises concerns about market concentration and pricing power among consolidated vendors.
**Forg365 PhaaS uses device code phishing and AI lures to compromise Microsoft 365 mailboxes, bypassing MFA. Priced at $400/month, it represents a major escalation in enterprise email attacks.**
The UK's National Crime Agency charged five suspects linked to Russian Coms, a caller ID spoofing platform that facilitated 1.8+ million scam calls. The enforcement action targets the infrastructure enabling mass telecom fraud across the UK and internationally.
Attackers used an AI-generated PowerShell script for Active Directory reconnaissance after gaining RDP access. Researchers identified it as LLM-generated through code patterns and over-engineered redundancy, demonstrating how AI is accelerating attack capabilities.
SOCs automate the wrong layer—wasting experts on routine alerts. Kahneman's System 1/System 2 framework reveals the fix: automate the predictable 98%, freeing experts for complex security investigations.
Meta's patent describes AI that monitors emotional states through speech transcription, tone analysis, eye tracking, and device usage across smartphones, glasses, and smart home devices. The all-day surveillance system raises significant privacy concerns.
Russian state hackers (FSB Center 16) are exploiting vulnerable routers to infiltrate critical infrastructure across energy, telecom, and government sectors. US and eight allied nations jointly warned of the systematic campaign targeting weak or default router configurations.
EU and UK impose sanctions on Russian military hackers, including GRU officers, for attacking European infrastructure. This marks their most comprehensive response to Moscow's cyber operations.
WorldLeaks stole 540K healthcare records from Centers Lab. Detection delays block industry-wide learning—supply chains are only as strong as their weakest vendor. (155 characters)